📦

otrs

Vendor: otrs

Actively Exploited 0 CISA KEV List
PoC / Exploits 10 Code Available
Total RCEs 8 Remote Access
Total CVEs 621 Total Indexed
Avg. EPSS 1.45% Exploit Prob.
Latest CVE CVE-2026-48209 Jun 01

Security Vulnerability Index

Page 3 / 63
7.2 CVSS

Improper Neutralization of commands allowed to be executed via OTRS System Configuration e.g. SchedulerCronTaskModule using UnitTests modules allows any authenticated attacker with admin privileges local execution of Code.This issue affects OTRS: from 7.0.X before 7.0.45, from 8.0.X before 8.0.35; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.

EPSS: 0.79%
7.6 CVSS

Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as Agent authenticated attacker to track user behaviour and to gain live insight into overall system usage. User IDs can easily be correlated with real names e. g. via ticket histories by any user. (Fuzzing for garnering other adjacent user/sensitive data). Subscribing to all possible push events could also lead to performance implications on the server side, depending on the size of the installation and the number of active users. (Flooding)This issue affects OTRS: from 8.0.X before 8.0.32.

EPSS: 0.53%
6.1 CVSS

An issue was discovered in Open Ticket Request System (OTRS) 6.0.x before 6.0.12. An attacker could send an e-mail message with a malicious link to an OTRS system or an agent. If a logged-in agent opens this link, it could cause the execution of JavaScript in the context of OTRS.

EPSS: 0.44%
7.4 CVSS

Improper Input Validation vulnerability in OTRS AG OTRS (ACL modules), OTRS AG ((OTRS)) Community Edition (ACL modules) allows Local Execution of Code. When creating/importing an ACL it was possible to inject code that gets executed via manipulated comments and ACL-names This issue affects OTRS: from 7.0.X before 7.0.42, from 8.0.X before 8.0.31; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.

EPSS: 0.30%
6.1 CVSS

Improper Input Validation vulnerability in OTRS AG OTRS (Ticket Actions modules), OTRS AG ((OTRS)) Community Edition (Ticket Actions modules) allows Cross-Site Scripting (XSS).This issue affects OTRS: from 7.0.X before 7.0.42; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.

EPSS: 0.43%
6.5 CVSS

Improper Input Validation vulnerability in OTRS AG OTRS, OTRS AG ((OTRS)) Community Edition allows SQL Injection via TicketSearch Webservice This issue affects OTRS: from 7.0.1 before 7.0.40 Patch 1, from 8.0.1 before 8.0.28 Patch 1; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.

EPSS: 0.71%
3.5 CVSS

Article template contents with sensitive data could be accessed from agents without permissions.

EPSS: 0.44%
7.5 CVSS

An external attacker is able to send a specially crafted email (with many recipients) and trigger a potential DoS of the system

EPSS: 0.56%
6.8 CVSS

Attacker might be able to execute malicious Perl code in the Template toolkit, by having the admin installing an unverified 3th party package

EPSS: 0.68%
4.6 CVSS

An attacker who is logged into OTRS as an admin user may manipulate customer URL field to store JavaScript code to be run later by any other agent when clicking the customer URL link. Then the stored JavaScript is executed in the context of OTRS. The same issue applies for the usage of external data sources e.g. database or ldap

EPSS: 0.45%